CVE-2026-105795Low· 3.1▾ SunlitKiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a consuming host that resolves the reference, allowing the host to cross the intended plugin-package boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code merely while generating the manifest, and impact requires downstream resolution of the unsafe reference. This issue is fixed in version 1.35.0.
kiota >= 1.25.1, < 1.35.0Microsoft.OpenApi.Kiota >= 1.25.1, < 1.35.0Microsoft.OpenApi.Kiota.Builder >= 1.25.1, < 1.35.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105796High· 8.8Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators
CVE-2021-40444High· 8.8Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows
CVE-2026-70200Critical· 10.0Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70009Critical· 9.3Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2021-27065High· 7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2024-21400Critical· 9.0Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability